AI governance: controls, oversight and fairness

How Orbio designs, monitors and audits its AI systems for HR processes, in line with the EU AI Act and the GDPR. The final decision always rests with people.

ISO/IEC 27001SOC 2 Type I & IIGDPREU AI ActISO/IEC 42001NYC Local Law 144

A support tool, never a decision-maker

Hiring AI is high-risk under Annex III of the EU AI Act — Orbio is designed from the ground up within that framework: it assists HR professionals, it does not replace them.

The system does not decide

Orbio does not admit, reject or hire candidates. It produces analyses and degrees of match that support the recruiting team's judgement — which retains final responsibility at all times.

The client defines the criteria

The system ships with no substantive criteria of its own. Your HR team defines the evaluation criteria, their weights and their rubrics for every position.

No comparison between people

Each application is evaluated individually against the position's criteria — never by ranking candidates against each other.

Candidates always informed

Conversational agents disclose from the first moment that they are AI, and the candidate can ask at any time to continue with a person from the recruiting team.

Five layers of control, from design to external audit

1

Responsible design

Technical separation of identifying data, exclusion of special categories, objective criteria defined by the client.

2

Pre-deployment validation

Every change to prompts, models or providers passes comparative and regression tests before production.

3

Production monitoring

Automatic evaluation after every analysis (LLM-as-judge): bias, hallucination and omission detection across 100% of real evaluations.

4

Human oversight

Weekly review by Orbio's technical team, and direct supervision by the client's HR team over every evaluation.

5

Independent audit

Monthly bias audits by Warden AI and annual penetration testing by a CREST-certified provider specialised in AI risk.

Independently audited, every month

30,000+

test CVs analysed every month by Warden AI, an independent third party

30,000+

conversations evaluated monthly with disparate-impact and counterfactual analysis

12

audits per year, with reports accessible to every client

The test set is generated by Warden, not by Orbio, and contains no client production data. Coverage spans sex, race/ethnicity, intersectional, age, disability, religion and sexual-orientation bias — with results published per protected category. An independent LLM-as-judge also reviews 100% of real production evaluations for bias, hallucination and omission.

Your data never trains a model

Your data never trains a model

DPAs with all model providers expressly prohibit using input data to train or improve their models, with zero-data-retention policies. Orbio uses pre-trained third-party models only — no fine-tuning on client data, ever.

EU data residency

Processing and storage in the EU (AWS eu-west-1, Ireland), with a US replica only for clients with US data-residency requirements. Encrypted in transit and at rest, per-client isolation enforced at the database-engine level.

Data minimisation by design

Identifying data (name, age, address, phone…) is separated from the start of every analysis and plays no part in the evaluation — which is based exclusively on experience, education, skills and languages.

Special categories excluded

Sensitive information (health, disability, trade-union membership…) is actively excluded from any classification — even when the candidate volunteers it.

Certified security, tested against AI-specific risks too

Annual AI-specific pentest

Offensive audit by an independent CREST-certified provider specialised in AI risk (OWASP guidelines for AI): infrastructure, application, and agent behaviour under manipulation.

Client-run testing

Your offensive-security team can run its own tests against the platform, coordinated with Orbio. The latest pentest report is shared on request.

Prompt-injection defence

Reduced attack surface through controlled context, structured prompts with isolated sections, and programmatic guardrails in the conversational agents.

Continuous protection

Permanent vulnerability and dependency scanning, centralised secret management, least-privilege access with MFA.

Business continuity

Redundant architecture with automatic backups, a periodically tested disaster recovery plan and a security incident response plan.

No change without validation

6,000+ automated tests, comparative and regression testing for any AI change, transparent versioning and immediate rollback.

Our bias audits are public

Warden AI publishes the results of every audit it runs on our systems, per regulation and per module. You do not have to take our word for any of it — read them yourself.

Secured by design, verified in practice

You should not have to choose between AI innovation and enterprise security. Orbio is built for regulated environments from the ground up.

Localized AI inference

LLM inference runs within the EU for EU clients, and follows data-sovereignty requirements for clients based in the Americas.

Zero training guarantee

Your data is never used to train AI models — contractually enforced with every provider and technically protected at every step.

Privacy by design

Data minimisation, consent management, transparency, and compliance with the GDPR and other regional privacy laws.

Prompt security

Defences against prompt injection and prompt tampering, with output filtering to prevent model misuse or leakage of sensitive information.

Infrastructure resilience

Environment isolation, encryption at rest and in transit, continuous vulnerability monitoring and proactive threat detection.

Strict access and audit controls

Role-based access, behavioural analysis, and an immutable audit trail capturing every user action and AI interaction.

AI observability

Full input and output logging, continuous response evaluation and prompt versioning, for controlled and inspectable AI behaviour.

Human-in-the-loop by default

Critical HR decisions require human validation. The agent recommends; a person decides, and the decision is recorded.

Explainable outputs

Transparent reasoning, source references and confidence scoring accompany every AI-generated conclusion.

The evidence, not just the claim

Certificates, audit reports and AI documentation are available through our Trust Center, continuously monitored and kept current. Sensitive documents are released on request.

ISO/IEC 27001:2022 certificate and surveillance audit report
SOC 2 Type I and Type II reports, with attestation confirmations
ISMS Statement of Applicability
Penetration test report, by a CREST-approved provider
AI System Description and instructions for use (AI Act Art. 13.3)
DPIA reference and Transfer Impact Assessment
Data Processing Agreements with all subprocessors
Full subprocessor register, with region and role
Vulnerability disclosure programme

Security questions or a vulnerability to report? security@orbio.work

Every evaluation can be reconstructed end to end

Every LLM call is centrally logged. For any individual evaluation the full chain can be reconstructed — incoming request, data consulted, prompt sent, response received, result shown. Each application keeps a chronological record of automatic analyses, transcripts, messages and human decisions, available to your audits.

Want to go deeper?

We're happy to walk your compliance, data-protection or security teams through any of these controls — including independent audit reports, the version changelog and certification status.